Course HomeLab PortalProject Portal

Course Glossary

Author & Course Lead — Badr Tajini · ESILV · 2026–2027

Term Operational meaning in this course
Artifact A file or image produced by a build and identified so it can be verified later.
Attestation Signed or verifiable metadata asserting how an artifact was produced.
Build context Files made available to a Docker build; reduce it with .dockerignore.
Capability A discrete Linux kernel privilege that can be dropped independently of UID 0.
CI Automated integration checks triggered by repository events.
CD Controlled delivery of a releasable artifact; automatic production deployment is not required here.
Claim A falsifiable statement about configuration or runtime behavior.
Compose A declarative model for a related set of containers on a Docker host.
Container A running or stopped process environment created from an image plus runtime configuration.
Control plane The component that decides desired state; Docker Engine has a daemon API, while Kubernetes adds a distributed reconciliation control plane.
Definition Versioned source such as a Dockerfile, Compose file, workflow or runbook.
Digest Content-addressed identifier; unlike a tag, it changes when content changes.
Docker daemon Privileged service managing Docker objects; access to its socket is effectively host-level control.
Dockerfile Ordered build definition for an image.
Entrypoint Executable a container starts as its primary process.
Evidence Captured output tied to a test and a claim.
Exit status Integer returned by a process; zero conventionally means success.
Git SHA Identifier of a Git commit used here to trace source to an image tag.
GHCR GitHub Container Registry.
Health check Repeated probe reporting process/service health; it is not automatically readiness.
Host port Socket on the Docker host mapped to a container port.
Image Immutable filesystem/configuration template used to create containers.
Image ID Local Docker identifier; not a portable release coordinate.
Immutable release Release selected by content digest and protected from silent tag movement.
Layer Content-addressed filesystem change reused across image builds.
Least privilege Grant only the identities, capabilities, mounts and network access required by the contract.
Loopback Address reachable only from the same network namespace, normally 127.0.0.1.
Multi-stage build Dockerfile with multiple build stages so tools and source need not enter the runtime image.
Negative test Test proving a prohibited behavior is denied for the intended reason.
Network namespace Kernel isolation of interfaces, routes and sockets for a process group.
OCI Open Container Initiative specifications for images, runtimes and distribution.
PID 1 First process in a container namespace, responsible for receiving signals and reaping children.
Positive test Test proving an explicitly allowed behavior succeeds.
Promotion Deliberate move of an already-built artifact into a later environment.
Readiness Ability to serve the complete dependency-backed request contract now.
Registry Service that stores and distributes images by repository, tag and digest.
Replayability Another engineer can rerun the documented test from declared preconditions.
Residual risk Known risk remaining after controls, with an owner or explicit acceptance.
Rollback Restore the previously recorded known-good release.
Rootless Docker Docker daemon and containers operated without a root-owned daemon; an extension topic.
Runtime contract Machine-readable declaration of ports, probes, configuration, persistence, resources, identity, shutdown and recovery.
SBOM Software bill of materials listing components in an artifact.
Secret Sensitive value requiring controlled injection, redaction and rotation.
Service discovery Resolution of a stable service name to a reachable endpoint inside a network.
Signal Kernel notification such as SIGTERM used for graceful shutdown.
Smoke test Cheap test proving the minimum runnable contract.
Tag Mutable human-readable image label; useful for discovery but insufficient as deployment identity.
Test card Structured link between claim, definition, test, result, evidence and recovery.
Threat model Explicit account of assets, trust boundaries, attacker abilities, abuse cases and mitigations.
Volume Docker-managed persistent data location independent of a container lifecycle.
Vulnerability triage Decision process that validates scanner findings, exposure, remediation and accepted residual risk.